4.3
    Medium

    CVE-2009-1798

    Last Modified: 18 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.

    Source:Jamal Pecou
    Published:28 Dec 2009
    4.3
    Medium

    CVE-2009-1789

    Last Modified: 23 Apr 2026

    mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.

    Source:Thomas Sader
    Published:26 May 2009
    7.5
    High

    CVE-2009-1787

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.

    Source:snakespc
    Published:26 May 2009
    6.9
    Medium

    CVE-2009-1786

    Last Modified: 16 Nov 2017

    The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.

    Source:inking
    Published:26 May 2009
    7.5
    High

    CVE-2009-1781

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.

    Source:scriptjunkie
    Published:22 May 2009
    7.5
    High

    CVE-2009-1780

    Last Modified: 23 Apr 2026

    admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

    Source:scriptjunkie
    Published:22 May 2009
    7.5
    High

    CVE-2009-1779

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.

    Source:scriptjunkie
    Published:22 May 2009
    6.8
    Medium

    CVE-2009-1778

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:YEnH4ckEr
    Published:22 May 2009
    5
    Medium

    CVE-2009-1777

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter.

    Source:USH
    Published:22 May 2009
    4.3
    Medium

    CVE-2009-1776

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via javascript: URIs in the (1) request and (2) return_link_url parameters.

    Source:USH
    Published:22 May 2009
    9.3
    Critical

    CVE-2009-1774

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to example/index.php. NOTE: this was originally reported as an issue affecting the do parameter, but traversal with that parameter might depend on a modified example/index.php. NOTE: some of these details are obtained from third party information.

    Source:[AVT]
    Published:22 May 2009
    7.5
    High

    CVE-2009-1771

    Last Modified: 23 Apr 2026

    index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.

    Source:ahmadbady
    Published:22 May 2009
    7.5
    High

    CVE-2009-1770

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:ahmadbady
    Published:22 May 2009
    5
    Medium

    CVE-2009-1768

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Br0ly
    Published:22 May 2009
    5
    Medium

    CVE-2009-1767

    Last Modified: 23 Apr 2026

    admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.

    Source:TiGeR-Dz
    Published:22 May 2009
    6.4
    Medium

    CVE-2009-1766

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mi4night
    Published:22 May 2009
    6.8
    Medium

    CVE-2009-1765

    Last Modified: 13 Dec 2016

    Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194.

    Source:ahmadbady
    Published:22 May 2009
    7.5
    High

    CVE-2009-1764

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action.

    Source:Securitylab.ir
    Published:22 May 2009
    9.3
    Critical

    CVE-2009-1759

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.

    Source:Michael Brooks
    Published:20 Apr 2009
    7.5
    High

    CVE-2009-1752

    Last Modified: 22 Nov 2016

    exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information.

    Source:ByALBAYX
    Published:21 May 2009
    7.5
    High

    CVE-2009-1751

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ThE g0bL!N
    Published:21 May 2009
    6
    Medium

    CVE-2009-1750

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Source:InjEctOr5
    Published:21 May 2009
    4.3
    Medium

    CVE-2009-1749

    Last Modified: 14 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.

    Source:ByALBAYX
    Published:21 May 2009
    7.5
    High

    CVE-2009-1748

    Last Modified: 14 Dec 2016

    Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.

    Source:ByALBAYX
    Published:21 May 2009
    7.5
    High

    CVE-2009-1747

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action.

    Source:snakespc
    Published:21 May 2009
    7.5
    High

    CVE-2009-1746

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:Cyber-Zone
    Published:21 May 2009
    4.3
    Medium

    CVE-2009-1744

    Last Modified: 23 Apr 2026

    InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash) via a crafted Hollywood FX Compressed Archive (.hfz) file.

    Source:Nine:Situations:Group
    Published:21 May 2009
    9.3
    Critical

    CVE-2009-1743

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to create and overwrite arbitrary files via a filename containing a ..\ (dot dot backslash) sequence in a Hollywood FX Compressed Archive (.hfz) file. NOTE: this can be leveraged for code execution by decompressing a file to a Startup folder. NOTE: some of these details are obtained from third party information.

    Source:Nine:Situations:Group
    Published:21 May 2009
    7.5
    High

    CVE-2009-1742

    Last Modified: 23 Apr 2026

    code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function.

    Source:Qabandi
    Published:20 May 2009
    6.8
    Medium

    CVE-2009-1741

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

    Source:snakespc
    Published:20 May 2009
    7.5
    High

    CVE-2009-1739

    Last Modified: 23 Apr 2026

    PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.

    Source:Mr.tro0oqy
    Published:20 May 2009
    7.5
    High

    CVE-2009-1736

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.

    Source:InjEctOr5
    Published:20 May 2009
    4.3
    Medium

    CVE-2009-1735

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. NOTE: some of these details are obtained from third party information.

    Source:snakespc
    Published:20 May 2009
    7.5
    High

    CVE-2009-1734

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:snakespc
    Published:20 May 2009
    10
    Critical

    CVE-2009-1730

    Last Modified: 10 Aug 2012

    Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command.

    Source:Metasploit
    Published:20 May 2009
    4.3
    Medium

    CVE-2009-1729

    Last Modified: 14 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.

    Source:SCS team
    Published:21 May 2009
    4.3
    Medium

    CVE-2009-1724

    Last Modified: 27 Apr 2014

    Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.

    Source:Gareth Hayes
    Published:20 May 2009
    7.5
    High

    CVE-2009-1699

    Last Modified: 26 Apr 2014

    The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."

    Source:Chris Evans
    Published:10 Jun 2009
    4.3
    Medium

    CVE-2009-1684

    Last Modified: 26 Apr 2014

    Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.

    Source:Michal Zalewski
    Published:10 Jun 2009
    7.5
    High

    CVE-2009-1678

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.

    Source:Nine:Situations:Group
    Published:18 May 2009
    6.5
    Medium

    CVE-2009-1677

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account's "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php.

    Source:Nine:Situations:Group
    Published:18 May 2009
    Low

    CVE-2009-1676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1535. Reason: This candidate is a duplicate of CVE-2009-1535. Notes: All CVE users should reference CVE-2009-1535 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:kingcope
    Published:18 May 2009
    9.3
    Critical

    CVE-2009-1675

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV command.

    Source:His0k4
    Published:18 May 2009
    9.3
    Critical

    CVE-2009-1674

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.

    Source:His0k4
    Published:18 May 2009
    9.3
    Critical

    CVE-2009-1672

    Last Modified: 23 Apr 2026

    The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

    Source:shinnai
    Published:18 May 2009
    9.3
    Critical

    CVE-2009-1671

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.

    Source:shinnai
    Published:18 May 2009
    7.5
    High

    CVE-2009-1670

    Last Modified: 23 Apr 2026

    user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Source:Mr.tro0oqy
    Published:18 May 2009
    10
    Critical

    CVE-2009-1669

    Last Modified: 23 Apr 2026

    The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.

    Source:Nine:Situations:Group
    Published:13 May 2009
    4
    Medium

    CVE-2009-1668

    Last Modified: 23 Apr 2026

    TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer.

    Source:Jonathan Salwan
    Published:18 May 2009
    9.3
    Critical

    CVE-2009-1667

    Last Modified: 12 Nov 2010

    Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long entry in a .m3u file, a different vector than CVE-2009-5137.

    Source:bibi-info
    Published:18 May 2009